SQLMap是专门针对SQL Injection进行检测的工具。XSSer(Cross Site Scripter)是专门针对Cross-Site Scripting进行检测的工具。因为这两种网站扫描工具和Web安全的关联度极高,而且针对性很强,因此,我把有关这两种工具的介绍放在后面章节中了,在这里不再重复介绍。
Nikto的官方网站是 https://cirt.net/Nikto2 ,如果有需要可以从中获得更多的信息。
测试环境如下所示。 虚拟化:VirtualBox 5.6.2 虚拟机:scanners(操作系统:Ubuntu 16.04.5 LTS, 安装软件:Nikto, IP地址: 虚拟机:target(操作系统:Ubuntu 16.04.5 LTS, 安装软件:Tomcat, IP地址:
root@scanners:~# apt install nikto
root@scanners:~# nikto -h -p 8080 - Nikto v2.1.5 --------------------------------------------------------------------------- + Target IP: + Target Hostname: target + Target Port: 8080 + Start Time: 2020-02-16 16:48:20 (GMT8) --------------------------------------------------------------------------- + Server: Apache-Coyote/1.1 + Server leaks inodes via ETags, header found with file /, fields: 0xW/1896 0x1581842166000 + The anti-clickjacking X-Frame-Options header is not present. + No CGI Directories found (use '-C all' to force check all possible dirs) + Allowed HTTP Methods: GET, HEAD, POST, PUT, DELETE, OPTIONS + OSVDB-397: HTTP method ('Allow' Header): 'PUT' method could allow clients to save files on the web server. + OSVDB-5646: HTTP method ('Allow' Header): 'DELETE' may allow clients to remove files on the web server. + /: Appears to be a default Apache Tomcat install. + /examples/servlets/index.html: Apache Tomcat default JSP pages present. + OSVDB-3720: /examples/jsp/snp/snoop.jsp: Displays information about page retrievals, including other users. + /manager/html: Default Tomcat Manager interface found + 6545 items checked: 0 error(s) and 9 item(s) reported on remote host + End Time: 2020-02-16 16:48:42 (GMT8) (22 seconds) --------------------------------------------------------------------------- + 1 host(s) tested root@scanners:~#